Economics of Ransomware: Risk Interdependence and Large-Scale Attacks
Bibliographic record
Abstract
Recently, the development of ransomware strains and changes in the marketplace for malware have greatly reduced the entry barrier for attackers to conduct large-scale ransomware attacks. In this paper, we examine how this mode of cyberattack impacts software vendors and consumer behavior. When victims face an added option to mitigate losses via a ransom payment, both the equilibrium market size and the vendor’s profit under optimal pricing can actually increase in the ransom demand. Profit can also increase in the scale of residual losses following a ransom payment (which reflect the trustworthiness of the ransomware operator). We show that for intermediate levels of risk, the vendor restricts software adoption by substantially hiking up price. This lies in stark contrast to outcomes in a benchmark case involving traditional malware (non-ransomware) where the vendor decreases price as security risk increases. Social welfare is higher under ransomware compared with the benchmark in both sufficiently low- and high-risk settings. However, for intermediate risk, it is better from a social standpoint if consumers do not have an option to pay ransom. We also show that the expected ransom paid is nonmonotone in risk, increasing when risk is moderate despite a decreasing ransom-paying population. For ransomware attacks on other vectors (beyond patchable vulnerabilities), there can still be an incentive to hike price. However, market size and profits instead weakly decrease in the ransom amount. When studying a generalized model that includes both traditional and ransomware attacks, our results remain robust to a wide range of scenarios, including threat landscapes where ransomware has only a small presence. This paper was accepted by Kartik Hosanagar, information systems. Funding: This work has been supported by the Haskayne School of Business' Dean's Research Grant and by an award from the Georgia Institute of Technology Center of International Business Education & Research as part of its funded research program. Supplemental Material: The online appendix is available at https://doi.org/10.1287/mnsc.2022.4300 .
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.002 | 0.006 |
| Meta-epidemiology (narrow) | 0.001 | 0.001 |
| Meta-epidemiology (broad) | 0.001 | 0.001 |
| Bibliometrics | 0.001 | 0.001 |
| Science and technology studies | 0.001 | 0.003 |
| Scholarly communication | 0.003 | 0.005 |
| Open science | 0.001 | 0.002 |
| Research integrity | 0.003 | 0.004 |
| Insufficient payload (model declined to judge) | 0.009 | 0.001 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".